A 250 million dollar bet that testing is not an event
Snehal Antani, who founded Horizon3 in 2019 with Anthony Pillitiere after both worked at Joint Special Operations Command, described the milestone in terms of earned permission rather than technology. The company invented the concept of AI hackers, he said, and spent six years earning the right to autonomously test the most critical networks. On 3 August the company announced a 250 million dollar Series E at a valuation above 2 billion dollars, co-led by returning investors NightDragon and NEA, with Acrew, Blue Cloud Ventures, EDBI, Demeter Group, PSG, SAIC and Sapphire joining, alongside existing backers including Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures and SignalFire.
The numbers behind the round describe a category being repriced rather than a single company doing well. Horizon3 reports annual recurring revenue approaching 100 million dollars with growth of 120 percent year on year, more than 7,000 organisations protected, four Fortune 10 enterprises as customers, and 310,000 tests run inside live production environments. Dave DeWalt, who founded NightDragon and previously ran FireEye and McAfee, joins the board along with NightDragon managing director Morgan Kyauk. The company opened an Amsterdam office in June and is extending into Australia and Singapore.
What European law actually requires, and how often
The Digital Operational Resilience Act sets the cadence for the firms most likely to buy this product. Articles 26 and 27 require identified financial entities to carry out advanced resilience testing by means of threat-led penetration testing at least every three years. Only entities considered significant, with sufficiently mature systems, fall into that obligation, and the standards for it were developed in line with the TIBER-EU framework, which was updated on 11 February 2025 to match the regulatory technical standards adopted under DORA.
Two details are worth fixing in your head before any budget conversation. First, financial entities are governed by DORA rather than NIS2, because Article 4 of NIS2 defers to the more specific regime, and firms regularly plan against the wrong one. Second, the cadence is a floor rather than a target. DORA began applying in January 2025, so a three-year cycle places the first complete threat-led test around January 2028 for entities in scope from the start, which is roughly eighteen months from now. The United Kingdom runs its own threat-led scheme for major firms on a comparable philosophy.
The artefact and the control are drifting apart
Here is the tension the funding round exposes. A threat-led penetration test is intelligence-driven, run by skilled humans against a scoped target, and it produces a document that satisfies a supervisor. Continuous automated testing produces something different: a rolling measurement of exploitable exposure. Horizon3's chief revenue officer Matt Hartley argues that a conventional engagement examines only two or three percent of a network once a year, while an autonomous platform can cover the whole estate continuously without taking production offline. That is a vendor's framing of a vendor's advantage and should be read as such, but the underlying observation about sampling is not controversial among people who commission these tests.
The honest counterweight is that automation does not replace what makes a threat-led test valuable. TLPT is built on threat intelligence about who would plausibly attack this specific institution and how, and a good red team invents attack paths no scanner enumerates. The two things are not substitutes, and a firm that cancels its human red team because it bought an autonomous platform has misread both. What is genuinely changing is the meaning of the three-year certificate. Passing in 2028 says the estate withstood a scoped, intelligence-led attack on one set of dates. It says nothing about the thousand days on either side, and the market has just put 250 million dollars behind the view that those days are where the exposure lives.
What to change in the next testing cycle
Start by writing down which regime binds you and on what date your next threat-led test is due. That sounds elementary, and it is the step most often skipped, because responsibility for the answer usually sits between a compliance function that knows the deadline and a security function that knows the estate. If your firm is in scope and DORA applied to you from January 2025, work backwards from early 2028 and note that scoping and threat intelligence work begins many months before the test itself.
Then treat the two activities as separate line items with separate purposes. The regulated test is a deliverable with a date, a scope agreed with a supervisor and an intelligence phase, and it should be budgeted as a project. Continuous testing is an operational control, and the question to ask a vendor is not how many findings it produces but how quickly a newly exposed asset appears in its results and how it behaves against live production. Ask for the failure record too, not just the count of tests run without disruption. A platform that has executed hundreds of thousands of production tests has a safety story worth examining in detail before it touches your core banking estate.
Read next: 45,601 Flaws This Year. 171 Are Being Used. | A Single Message Reached the Host's SSH Keys


